CVE-2024-32867: Suricata's defrag contains various issues leading to policy bypass
Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to 7.0.5 and 6.0.19, various problems in handling of fragmentation anomalies can lead to mis-detection of rules and policy. This vulnerability is fixed in 7.0.5 or 6.0.19.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2024-32867?
CVE-2024-32867 is classified as a vulnerability that can lead to mis-detection of rules in the Suricata network security software.
How do I fix CVE-2024-32867?
To fix CVE-2024-32867, upgrade Suricata to versions 7.0.5 or 6.0.19 or later.
What versions of Suricata are affected by CVE-2024-32867?
Suricata versions prior to 7.0.5 and 6.0.19 are affected by CVE-2024-32867.
What types of issues does CVE-2024-32867 cause?
CVE-2024-32867 causes various problems in handling fragmentation anomalies, leading to mis-detection of rules and policies.
Is there a workaround for CVE-2024-32867?
There are no known workarounds for CVE-2024-32867; upgrading to the patched versions is recommended.